Courseiva

DEA-C01 Data Operations and Support Practice Question

A data engineer is troubleshooting an AWS Glue job that reads from an Apache Kafka topic using a Glue connector. The job fails with 'TimeoutException'. The Kafka cluster is in a VPC. Which step should the engineer take FIRST?

⚠ Common exam trap

The trap is jumping to application-layer fixes (session timeout, connector version, job type) when the error is a network-layer TimeoutException — candidates forget that in AWS, 'timeout' almost always means security group, NACL, or route table, not a code or configuration parameter.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check the security group and network ACLs associated with the Glue job's VPC.

A TimeoutException from a Glue job reading Kafka in a VPC almost always indicates a network connectivity problem between the Glue job's ENIs and the Kafka brokers. The first step is to verify that the security groups and network ACLs allow traffic on the Kafka ports (typically 9092/9093) between the Glue job's subnet and the Kafka cluster's subnet. This is the most common root cause and the fastest to check.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Check the security group and network ACLs associated with the Glue job's VPC.

    Why this is correct

    A TimeoutException when a Glue connector reaches a Kafka cluster inside a VPC most often means connectivity is blocked, not that Kafka is misconfigured. Security groups and network ACLs are the first hop to verify, since either can silently drop traffic on the required broker ports.

  • ✗

    Increase the Kafka consumer session timeout.

    Why it's wrong here

    Raising the session timeout only extends how long the consumer waits before declaring a broker dead; it cannot establish a connection that never forms. Session timeout tuning is appropriate when consumers are evicted during long processing pauses, not when the job cannot reach brokers in a VPC at all.

  • ✗

    Update the Glue connector to the latest version.

    Why it's wrong here

    Upgrading the connector version does not create the network path to the Kafka brokers; a TimeoutException from inside a VPC indicates missing connectivity, such as subnet, security group or route configuration. Version upgrades address connector bugs or feature gaps, and would be reasonable once connectivity is confirmed working.

  • ✗

    Change the Glue job type from Spark to Python Shell.

    Why it's wrong here

    Python Shell jobs run single-node Python scripts and cannot use Glue's Kafka connector or distributed Spark reader, so the VPC connectivity problem persists. It is tempting because Python Shell suits small ETL scripts and lightweight transforms, but not streaming reads from Kafka across a VPC.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.